The FBI and IC3 published a joint PSA after Kali365, a Telegram marketed Phishing‑as‑a‑Service observed in April 2026, was found automating OAuth Device Authorization phishing to capture Microsoft 365 access. The phishing kit packages the full attack chain: AI-written lures, multilingual templates, dynamic device‑code generation, live cookie capture panels, and affiliate access which makes it easy for low-skill actors to run high‑volume campaigns.
Uses on‑demand device codes and clipboard tricks to remove timing issues, raising success rates.
Automates the full attack chain.
Refresh cookies provide persistent, stealthy access across services without needing passwords.
Requires user interaction (victim must paste the code).
Visible account activity or security alerts, token revocation and conditional access policies can detect or block misuse.
Reliant on OAuth/device‑flow implementations, rate limits and device code policies reduce effectiveness.
@arch
